Skip to main content

Privacy

Information provided pursuant to Article 13 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

1. GENERAL INFORMATION

In compliance with Articles 12 and 13 of Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”), this page describes the processing of personal data carried out by the Joint Data Controllers, as defined in point 2 below, in relation to the data subjects involved in the processing activities listed below (“data subjects”).

This privacy notice does not apply to other processing activities carried out by browsing websites that may be accessed through links contained within this website.

2. JOINT DATA CONTROLLERS

The Joint Data Controllers listed below wish to provide data subjects with the essential content of the joint controllership agreement signed pursuant to Article 26 of Regulation (EU) 2016/679, and to inform them about the processing of the personal data collected.

  • Florim Ceramiche S.P.A. SB (hereinafter “FLORIM”), with registered office in via Canaletto 24, 41042 Fiorano Modenese (MO), VAT and Tax Code IT012653320364, represented by its legal representative pro tempore.
  • Falper srl (hereinafter “FALPER”), with registered office in Via Veneto, 7/9, Ozzano dell’Emilia, Bologna, 40064; VAT No. 00514511203; Tax Code 00549000370, represented by its legal representative pro tempore.

The Joint Data Controllers have entered into an agreement regarding their joint role, committing to the coordinated delivery of services related to the organization and management of events, collection and recording of data concerning the data subjects, and the provision of services related to “ELITIQUE” events addressed to the data subjects.

This agreement regulates the responsibilities assigned to each Controller solely in relation to data processing activities arising from the “ELITIQUE” project.

3. DATA PROTECTION OFFICERS

Florim Ceramiche S.P.A. SB has appointed a Data Protection Officer (DPO), in accordance with Articles 37–39 of Regulation (EU) 2016/679 (GDPR). Any requests may be sent to the following email address: privacydpo@florim.com

Falper srl has not appointed a Data Protection Officer (DPO), as it does not fall within the cases provided for by Articles 37–39 of Regulation (EU) 2016/679 (GDPR).

4. TYPES OF DATA PROCESSING

4.1 DATA COLLECTED THROUGH CONTACT REQUESTS FOR THE ELITIQUE PROJECT

Managing contact requests submitted via the forms available on this website involves the acquisition of the data subject’s/user’s personal data.

Purpose of processing

(Art. 13, para. 1, letter c) of the GDPR)

The personal data collected are used solely for the purpose of responding to the requests submitted and communicating with the data subject during any subsequent phases. Some information (such as the requester’s field of occupation and the company’s location) is collected to optimize the process of forwarding the requests to the appropriate corporate departments, based on territory and product sector.

Providing certain data is mandatory and indicated by specific asterisks.

Categories of personal data

  • personal details (first name, last name),
  • contact information (email address, phone number),
  • professional information (field of occupation, company, company location),
  • any other data/information included in the request.

Lawfulness of processing

(Art. 13, para. 1, letter c) of the GDPR)

The processing is carried out in order to perform an activity requested by the data subject (Art. 6, para. 1, letter b) of the GDPR).

Scope of data disclosure

(Art. 13, para. 1, letters e) and f) of the GDPR)

The data are processed exclusively by authorized personnel, trained and properly instructed in data handling. They may also be processed by other parties engaged by the Joint Controllers for purposes related to the processing itself (such as website management support or consulting firms). These parties act as data processors and have signed specific agreements with the Joint Controllers pursuant to Article 28, para. 3 of the GDPR.

In any case, the personal data collected will not be disclosed to third parties, nor will they be disseminated or transferred outside the European Union/European Economic Area.

Processing methods

(Recital 39, GDPR)

Personal data are processed lawfully, fairly, and transparently, in accordance with the principles established by current legislation. The processing of personal data is carried out using IT and automated tools. Considering the nature and characteristics of the processing, the Joint Controllers have adopted technical and organizational security measures aimed at limiting or eliminating the risks of data loss, unlawful or improper use, or unauthorized access.

Data retention period

(Art. 13, para. 2, letter a) of the GDPR)

Personal data are retained for the time necessary to manage the relationship with the requester.

Nature of data provision

(Art. 13, para. 2, letter e) of the GDPR)

The data are provided voluntarily by the data subjects. However, failure to provide them may affect the handling of the request and the ability to respond.

4.2 DATA COLLECTED FOR SUBSCRIPTION TO CUSTOMIZED INFORMATIONAL NEWSLETTERS – ELITIQUE PROJECT

Personal data are processed for purposes related to the sending of informational newsletters about the ELITIQUE project, following the completion of specific forms by data subjects on this website.

Purpose of processing

(Art. 13, para. 1, letter c) of the GDPR)

By completing specific forms on this website, personal data are collected in order to send the data subject periodic communications about the ELITIQUE project.

These communications will be sent as newsletters to the email address provided by the data subject and may – in some cases – be customized.

Categories of personal data

  • personal details (first name, last name);
  • contact information (email address);
  • professional information (field of occupation);
  • personal information (country).

Lawfulness of processing

(Art. 13, para. 1, letter c) of the GDPR)

The processing of personal data is carried out for the purposes and in the manner described in this paragraph with the consent of the data subject (Art. 6, para. 1, letter a) of the GDPR).

Scope of data disclosure

(Art. 13, para. 1, letters e) and f) of the GDPR)

The data are processed exclusively by authorized personnel, trained and properly instructed in data handling. They may also be processed by other parties engaged by the Joint Controllers for purposes related to the processing itself (such as website management support, consulting firms, customer service providers). In some cases, these parties act as data processors and have signed specific agreements with the Joint Controllers pursuant to Article 28, para. 3 of the GDPR.

In any case, personal data will not be disclosed to third parties, nor will they be disseminated or transferred outside the European Union/European Economic Area.

Processing methods

(Recital 39, GDPR)

Personal data are processed lawfully, fairly, and transparently, in accordance with the principles established by current legislation. The processing is carried out using IT and automated tools.

Newsletter profiling and customization will be based on the following criteria: (i) territorial/geographical, taking into account the data subject’s country; (ii) the data subject’s field of occupation.

Considering the nature and characteristics of the processing, the Joint Controllers have adopted technical and organizational security measures aimed at limiting or eliminating the risks of data loss, unlawful or improper use, or unauthorized access.

Data retention period

(Art. 13, para. 2, letter a) of the GDPR)

Personal data are retained for the time necessary to manage the relationship with the requester.

Nature of data provision

(Art. 13, para. 2, letter e) of the GDPR)

The provision of personal data for the above-mentioned purposes is optional; however, failure to provide such data may affect the proper delivery of the requested informational newsletters.

4.3 IMAGES CAPTURED DURING PARTICIPATION IN “ELITIQUE” EVENTS

During participation in events organized or hosted by the Joint Data Controllers, data subjects may be recorded or photographed.

Purpose of processing

(Art. 13, para. 1, letter c) of the GDPR)

Participants in events held at the premises of the Joint Data Controllers may be recorded and photographed. The material will be used for communication and promotional purposes related to the “ELITIQUE” project and may be published on websites, social media, media outlets, and in the press.

The Joint Data Controllers guarantee that the images will not be used in contexts that could compromise the personal dignity or decorum of the data subjects. The use of images is free of charge, and no claims may be made in the future in this regard.

Lawfulness of processing

(Art. 13, para. 1, letter c) of the GDPR)

The processing of personal data is carried out both by virtue of contractual obligations (services to be provided to the data subject for participation in “ELITIQUE” events) and, with regard to data processing not necessary for fulfilling contractual obligations and/or services requested by the data subject (e.g. marketing purposes), on the basis of the data subject’s consent (Art. 6, para. 1, letter a) of the GDPR). Any such consent will be obtained during the events in which the data subject participates.

Scope of data disclosure

(Art. 13, para. 1, letters e) and f) of the GDPR)

The data are processed exclusively by authorized personnel who are trained and properly instructed in data handling. They may also be processed by other parties engaged by the Joint Controllers for purposes related to the processing itself (e.g., IT system management support; event organization companies; marketing and communication agencies; etc.). In some cases, these parties act as data processors and have signed specific agreements with the Joint Controllers pursuant to Article 28, para. 3 of the GDPR. Data may also be disclosed to competent authorities in specific cases.

Images may also be disclosed to third parties and disseminated via websites, communication tools, press media, social networks, social media, television, publication in magazines, presentations at seminars and conferences, etc.

Processing methods

(Recital 39, GDPR)

Personal data are processed lawfully, fairly, and transparently, in accordance with the principles established by current legislation. The processing is carried out using IT and automated tools.

Considering the nature and characteristics of the processing, the Joint Controllers have adopted technical and organizational security measures aimed at limiting or eliminating the risks of data loss, unlawful or improper use, or unauthorized access.

Data Retention Period

(Art. 13, para. 2, letter a) of the GDPR)

With the exception of data subject to dissemination, personal data will be retained for the time necessary to fulfill the purposes outlined above.

Nature of data provision

(Art. 13, para. 2, letter e) of the GDPR)

The provision of data is optional and subject to the data subject’s consent. However, without such consent, it will not be possible to access the Controller’s premises or participate in the event.

4.4 BROWSING DATA

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses or domain names of the computers used by users who connect to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful, error, etc.), and other parameters related to the user’s operating system and IT environment.

Purpose of processing

(Art. 13, para. 1, letter c) of the GDPR)

These data are used solely to obtain statistical information on the use of the website and to ensure its proper functioning. The data may also be used to determine liability in the event of potential cybercrimes against the website (legitimate interests of the Joint Data Controllers).

Lawfulness of processing

(Art. 13, para. 1, letter c) of the GDPR)

The processing is necessary for the purposes of the legitimate interests pursued by the Joint Data Controllers in ensuring the security of their IT system and assessing the use and performance of the website (Art. 6, para. 1, letter f) of the GDPR).

Scope of data disclosure

(Art. 13, para. 1, letters e) and f) of the GDPR)

The data are processed exclusively by authorized personnel who are trained and properly instructed in data handling. They may also be processed by other parties engaged by the Joint Controllers for purposes related to the processing itself (e.g., support for the management of IT systems and this website). In some cases, these parties act as data processors and have signed specific agreements with the Joint Controllers pursuant to Article 28, para. 3 of the GDPR. Data may be disclosed to competent authorities in specific cases.

In any case, personal data will not be disclosed to third parties, nor will they be disseminated or transferred outside the European Union/European Economic Area.

Processing methods

(Recital 39, GDPR)

Personal data are processed lawfully, fairly, and transparently, in accordance with the principles established by current legislation. The processing is carried out using IT and automated tools.

Considering the nature and characteristics of the processing, the Joint Controllers have adopted technical and organizational security measures aimed at limiting or eliminating the risks of data loss, unlawful or improper use, or unauthorized access.

Data Retention Period

(Art. 13, par. 2, lett. a), of the GDPR)

The data are generally retained for the fulfillment of the purposes outlined above, for short periods of time, except in the event of extensions related to investigation activities.

Nature of data provision

(Art. 13, para. 2, letter e) of the GDPR)

​The provision of data is implicit in accessing and browsing the website.​

4.5 COOKIES

For more general information about cookies and how to enable or disable them, please refer to the Cookie Policy document.

5. DATA SUBJECT RIGHTS (GDPR Articles 15–22)

At any time, the data subject may exercise the following rights:

  • request confirmation as to whether their personal data are being processed;
  • obtain information regarding the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be disclosed, and the data retention period (or, if not possible, the criteria used to determine it);
  • obtain the rectification or erasure of the data;
  • obtain restriction of processing under the conditions and in the cases provided for by current legislation;
  • obtain data portability in the cases provided for by current legislation, meaning the right to receive the data from a data controller in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance;
  • object to the processing at any time in the cases provided for by current legislation, including processing for direct marketing purposes;
  • lodge a complaint with the Data Protection Authority (Garante per la protezione dei dati personali), according to the procedures established by the Authority.

Requests must be addressed to the Joint Data Controllers by writing to the following email address: privacyElitique@florim.com for the processing activities described above.